foundry-mari
Triggered rules
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:13
source=(https://thefoundry.s3.amazonaws.com/products/mari/releases/$pkgver/Mari$pkgver-linux-x86-release-64.run)
llm_review
An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 72%): The PKGBUILD downloads a prebuilt binary installer (.run file) from thefoundry.s3.amazonaws.com and executes it during the package() phase. While The Foundry (now Foundry) is a legitimate commercial software vendor and S3 is a plausible distribution channel for them, this is not the canonical foundry.com download domain. The .run installer is executed directly with --accept-eula and --prefix flags, meaning arbitrary code from that binary runs during packaging. The md5sums check provides weak integrity assurance (MD5 is cryptographically broken). The real concern is that an S3 bucket URL is less stable and verifiable than a primary vendor domain — bucket names can be squatted or misconfigured — and executing a prebuilt binary installer is a genuine supply-chain risk. This is a legitimate medium: not clearly malicious, but an executed binary from a non-primary host with weak integrity checking.
PKGBUILD
1 offending line(s) highlighted# Maintainer: Adrià Cabello <adro.cc79 at protonmail dot com>
pkgname=foundry-mari
_pkgver_major=7
_pkgver_minor=0
_pkgver_build=1
pkgver=${_pkgver_major}.${_pkgver_minor}v${_pkgver_build}
pkgrel=1
pkgdesc="3D Painting Industry Standard Tool for complex assets"
arch=('x86_64')
license=('Custom: The Foundry')
provides=('mari')
url="https://www.foundry.com/products/mari"
source=(https://thefoundry.s3.amazonaws.com/products/mari/releases/$pkgver/Mari$pkgver-linux-x86-release-64.run)
md5sums=('0e54fdbb0396982964227dc7680e1513')
package() {
mkdir -p "${pkgdir}/opt/mari"
mkdir -p "${pkgdir}/usr/bin"
chmod +x Mari$pkgver-linux-x86-release-64.run
./Mari$pkgver-linux-x86-release-64.run --prefix=${pkgdir}/opt/mari --accept-eula
ln -s "/opt/mari/mari" "${pkgdir}/usr/bin/mari"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | MEDIUM | 2 |
| 2026-08-02 00:16:08 | MEDIUM | 2 |
| 2026-08-01 00:11:18 | MEDIUM | 2 |
| 2026-07-31 00:14:10 | MEDIUM | 2 |
| 2026-07-30 00:17:23 | MEDIUM | 2 |
| 2026-07-29 00:25:53 | MEDIUM | 2 |
| 2026-07-28 00:07:28 | MEDIUM | 2 |
| 2026-07-27 00:24:32 | MEDIUM | 2 |
| 2026-07-26 00:07:32 | MEDIUM | 2 |
| 2026-07-25 00:13:44 | MEDIUM | 2 |
| 2026-07-24 00:02:28 | MEDIUM | 2 |
| 2026-07-23 00:14:47 | MEDIUM | 2 |
| 2026-07-22 00:29:32 | MEDIUM | 2 |
| 2026-07-21 00:24:15 | MEDIUM | 2 |
| 2026-07-20 00:19:49 | MEDIUM | 2 |
| 2026-07-19 00:17:08 | MEDIUM | 2 |
| 2026-07-18 00:14:48 | MEDIUM | 2 |
| 2026-07-17 00:06:16 | MEDIUM | 2 |
| 2026-07-16 00:05:41 | MEDIUM | 2 |
| 2026-07-15 00:09:25 | MEDIUM | 2 |